CVEs

CVEs

This is the full list of CVEs that I have discovered and that have been published.

CVE IDDateDescriptionExploit LinkBlog Link
CVE-2024-37042024-04-11SQL injection in OpenGnsys 1.1.1d allowing login bypass and database access.INCIBE advisory

OpenGnsys patch
CVE-2024-37052024-04-11Unrestricted file upload in OpenGnsys 1.1.1d allowing webshell upload.INCIBE advisory

OpenGnsys patch
CVE-2024-37062024-04-11Information exposure in OpenGnsys 1.1.1d leaking database credentials.INCIBE advisory

OpenGnsys patch
CVE-2024-37072024-04-11Information exposure in OpenGnsys 1.1.1d allowing web-tree file enumeration.INCIBE advisory

OpenGnsys patch
CVE-2024-13432024-02-19Weak backup directory permissions in LaborOfficeFree 19.10 allowing backup file access.INCIBE advisory
CVE-2024-13442024-02-19Recoverable database credentials in LaborOfficeFree 19.10 enabling privileged database access.INCIBE advisory
CVE-2024-13452024-02-19Weak MySQL root password in LaborOfficeFree 19.10 vulnerable to brute force.INCIBE advisory
CVE-2024-13462024-02-19Predictable MySQL root password in LaborOfficeFree 19.10 derived from constants.GitHub PoC

Exploit-DB
INCIBE advisory
CVE-2024-7481

ZDI-24-1290
2024-08-20TeamViewer driver signature verification flaw allowing local privilege escalation via printer driver installation.GitHub PoCFinding TeamViewer 0days - Part III

ZDI-24-1290

TeamViewer bulletin
CVE-2024-7479

ZDI-24-1289
2024-08-20TeamViewer driver signature verification flaw allowing local privilege escalation via VPN driver installation.GitHub PoCFinding TeamViewer 0days - Part III

ZDI-24-1289

TeamViewer bulletin
CVE-2025-406782025-08-02Dangerous file upload in Summar Portal del Empleado via the absence attachment endpoint.INCIBE advisory

GitHub advisory
CVE-2025-406772025-10-10SQL injection in Summar Portal del Empleado allowing database read/write operations.GitHub PoC

Exploit-DB
INCIBE advisory
CVE-2025-686862025-12-01FortiOS information exposure allowing bypass of the symbolic-link persistence patch after prior compromise.Checker Tool - GitHubFortiGate Symlink Persistence Method

ITRES patch-bypass writeup

Fortinet PSIRT
CVE-2026-80762026-02-15Weak PIN-based credentials in CashDro 3 enabling brute-force access to administration.Cashdro Vulnerabilities: From Pentest to Stealing Money

INCIBE advisory
CVE-2026-80772026-04-20Missing backend authorization in CashDro 3 allowing privilege escalation to administrator.Cashdro Vulnerabilities: From Pentest to Stealing Money

INCIBE advisory